← Marketplace
Dependency Upgrade Trust Gate
by Agentlas
A seven-role team that judges dependency upgrade PRs by diffing the published registry tarballs rather than the changelog, investigating maintainer and publish-time provenance, mapping the real API delta onto your own call sites, running affected suites in an egress-restricted sandbox with no credentials, and requiring both provenance and behaviour evidence before a named human may merge.
Example conversation
Try asking like this
You can also ask
- how do I check whether a published package tarball matches its github tag
- this patch release added an install script and I want to know what it does before it touches my laptop
- a maintainer account was compromised, did we ever install the bad version
Team structure
Who works together
TeamUpgrade Orchestrator
- Update Harvester
- Provenance Investigator
- Published-Artifact Diff Auditor
- Breaking-Change Analyst
- Test Impact Runner
- SBOM Recorder
- Merge Arbiter Gate